Impact
The vulnerability stems from an insufficient enforcement of content security policy in Chrome’s ServiceWorker implementation. A specially crafted HTML page can cause the browser to ignore the specified policy, allowing the attacker’s script to run with the same privileges as the page. This enables execution of arbitrary code within the page context and can lead to further data theft or interaction with other web applications if the user visits the malicious site.
Affected Systems
Google Chrome releases prior to version 147.0.7727.55 are affected. The issue is present across all operating systems supported by Chrome, including Windows, macOS, and Linux.
Risk and Exploitability
The CVSS base score of 4.3 marks it as low severity, and the EPSS score is below 1%, indicating a low likelihood of exploitation. It is not listed in CISA’s KEV catalog. Exploitation requires only that a user load a crafted web page; no additional privileges or software are needed, making the attack vector remote and user‑initiated.
OpenCVE Enrichment
Debian DSA